Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects high-volume credential brute-forcing activity targeting Dahua IP camera administrative interfaces (Ports 80/37777). The rule identifies a pattern of multiple connection failures across multiple distinct targets followed by a successful connection, which is highly characteristic of automated credential stuffing or password spraying attacks against embedded IoT devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule detects potential smishing or malvertising attacks by monitoring network activity for the download of .apk files from non-reputable domains. It correlates these download attempts with previous browsing behavior on URLs containing specific 'fake app-store' lure patterns (e.g., promotional text like 'Nexus One' or 'Download Now' outside of official marketplaces like Google Play, APKMirror, or APKPure).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the execution of PowerShell via WScript or CScript scripts that contain command line arguments indicative of a file download cradle (e.g., Invoke-WebRequest, IWR, Net.WebClient, DownloadFile, DownloadString, or BITS transfer). This pattern is frequently used by adversaries to download and execute second-stage payloads or RMM agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects HTTP requests to Vercel deployment domains where the requested resource is a specific phishing kit asset ('font1.woff2'). This pattern is commonly associated with phishing campaigns hosted on free web hosting platforms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects unauthorized processes, excluding standard web browsers, accessing sensitive browser files such as Login Data, Cookies, Web Data, and Local State. This activity is indicative of credential harvesting malware attempting to steal authentication cookies, saved passwords, or browser profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects a malicious payload masquerading as a ClaudeDesktop installer that uses DLL sideloading via a tampered libcef.dll and a repurposed JetBrains binary to execute the SectopRAT .NET RAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule detects network activity and cloud API events indicative of an adversary utilizing the VAPI.ai platform to orchestrate automated voice-phishing (vishing) campaigns. It correlates outbound network connections to VAPI.ai endpoints with specific webhook callback patterns used to track call status for victim records.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
103
Detects instances where rundll32.exe is used to invoke shell32.dll with the SHCreateLocal function, or where a web browser process (msedge.exe, chrome.exe, or firefox.exe) is spawned by rundll32.exe to open an HTML file. This pattern is often indicative of malicious activity such as HTML smuggling or local file execution attacks where rundll32 is used as a proxy to open files via the browser.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the creation or presence of Windows Shortcut (LNK) files that use deceptive double extensions (e.g., .pdf.lnk) and specific filenames related to South Korean financial reporting, a technique associated with the threat actor Kimsuky to entice users into executing malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects network activity associated with the 'VPN-for-X' browser extension, specifically targeting communication with external services used for proxy configuration fetching and dead-drop proxy list retrieval. This includes TLS SNI checks for GitHub, Blogspot, and Telegram, as well as specific URI requests for proxy configurations and server lists.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects instances where a process spawns a child process using the exact same executable image path, specifically when the executable is located in user-writable directories such as Downloads or AppData\Local\Temp. This behavior is a common indicator of process hollowing or self-injection techniques used by malware, such as loaders that decrypt payloads in memory and then spawn a new, hollowed instance of themselves to execute the malicious code, frequently observed during post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects network traffic to specific domains (api.hhos.ru, mainapi.store) associated with the VPN-for-X browser extension's monetization API. This behavior is indicative of command-and-control or tracking communication identified as potentially malicious within the context of a browser extension.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects anomalous outbound HTTP/TLS requests to rutracker.org that contain a GUID-like identifier in the URI or deviate from normal user traffic patterns, which is characteristic of the 'VPN-for-X' browser extension acting as a command-and-control beacon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects HTTP CONNECT requests to external networks that include Proxy-Authorization headers with Basic authentication. This pattern is indicative of malicious proxy tunneling or unauthorized credential usage for bypassing security controls or establishing command and control channels via a proxy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects Microsoft Entra OAuth 2.0 device authorization grant flow completion immediately followed by non-interactive API access from automated user agents like python-requests. This behavior is indicative of device code phishing kits, where an attacker tricks a user into entering a code and then programmatically hijacks the resulting session token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects network activity associated with the GhostCode phishing kit backend. The rule monitors for specific API endpoints used for credential and MFA harvesting, including loading configurations, geolocation, and polling for captured data, combined with specific session cookie identifiers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects sign-in events using the OAuth 2.0 device code flow, which is a mechanism often abused in phishing campaigns (such as GhostCode) to lure users into authorizing malicious applications or granting access tokens without needing their actual credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects suspicious non-interactive Entra ID sign-in events using the 'python-requests' User-Agent against sensitive Microsoft resources such as Microsoft Graph, Device Registration, or Intune. This activity is indicative of automated token abuse, particularly in the context of device-code phishing kits (e.g., GhostCode), where an attacker uses stolen session information to interact with Microsoft APIs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the Redis server process writing or modifying files within cron configuration directories. This is a common persistence technique used by attackers to gain recurring execution after exploiting vulnerable or misconfigured Redis instances.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
KQL Query from file: Detect O365 Activities from OpenAI IP Addresses
avatar
Steven Lim@KQLWizard
avatar
SlimKQL 2026
29 days ago
1715722
Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
19 days ago
1014